ZeroHour

CVE-2026-3911

CVSS 3.1
2.7 low
EPSS
<1%p26
Published
()
Modified
Description

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

Vendors
redhat
Products
build of keycloak
Weakness
CWE-359
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.